
CVE-2021-22005 Patches are not enough for VMWare vCenter Server and Cloud Foundation vulns -- https://www.mitiga.io/blog/patches-vmware-vcenter-server-cloud-foundation-vulns
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.
Priority
LOW
Exploitation
ACTIVE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
3 versions affected across 2 products

CVE-2021-22005 Patches are not enough for VMWare vCenter Server and Cloud Foundation vulns -- https://www.mitiga.io/blog/patches-vmware-vcenter-server-cloud-foundation-vulns
4 of 4 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | vmware | cloud_foundation | - | - | - |
| App | vmware | vcenter_server | 6.5 | - | - |
| App | vmware | vcenter_server | 6.7 | - | - |
| App | vmware | vcenter_server | 7.0 | - | - |